googleapis / googleapis/google-http-java-client
Core: XmlPullParser processes external DTD entities (XXE) — disable FEATURE_PROCESS_DOCDECL in Xml#createParser()
- Lingua principale
- Java
- Stelle
- 1.4k
- Fork
- 473
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
**Environment details**
1. Core (XML) — Xml#createParser() in google-http-client-xml
2. OS type and version: Any (JVM-level issue, not OS-specific)
3. Java version: Any (Java 8+)
4. google-http-client-xml version: 2.1.1 and earlier
---
**Problem Statement**
Xml#createParser() returns a raw XmlPullParser without disabling
XmlPullParser.FEATURE_PROCESS_DOCDECL. If an attacker can influence the XML content
parsed by the library (e.g. via a malicious server response or injected content), they can
embed a declaration with external entity references (),
causing the parser to resolve arbitrary external entities.
This is a classic XML External Entity (XXE) vulnerability.
---
**Steps to reproduce**
1. Call Xml.createParser() and feed it XML containing an inline DTD with entity
declarations ( ]>).
2. Parse the document with Xml.parseElement(...).
3. Observe that the entity &xxe; is resolved and its value appears in the parsed output
instead of being rejected or left unexpanded.
---
**Code example**
XmlPullParser parser = Xml.createParser();
String xmlWithDtd = "\n"
+ "\n"
+ "]>\n"
+ "&xxe;";
parser.setInput(new StringReader(xmlWithDtd));
SimpleTypeString result = new SimpleTypeString();
Xml.parseElement(parser, result, new XmlNamespaceDictionary().set("", ""), null);
// result.value == "injected" <-- DTD entity resolved, XXE confirmed
---
**Security Impact**
- Allows entity injection / content spoofing from malicious XML input.
- In environments parsing untrusted XML (e.g. API responses from attacker-controlled
servers), this could lead to information disclosure or server-side request forgery (SSRF)
if external URI entities are supported by the underlying parser implementation.
---
**Proposed Fix**
Set FEATURE_PROCESS_DOCDECL to false immediately after creating the parser, with a
graceful fallback for parsers that do not support the feature flag:
public static XmlPullParser createParser() throws XmlPullParserException {
XmlPullParser parser = getParserFactory().newPullParser();
try {
parser.setFeature(XmlPullParser.FEATURE_PROCESS_DOCDECL, false);
} catch (XmlPullParserException e) {
// Ignore if the feature is not supported by this parser implementation
}
return parser;
}
A regression test (testCreateParser_disablesDocDecl) is included in the accompanying PR
verifying that DTD entity content is not resolved (or that the parser throws, which is also
an acceptable safe outcome).
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start at Xml#createParser() in the google-http-client-xml module and inspect how the new XmlPullParser is configured. Run or add the named regression test, testCreateParser_disablesDocDecl, using the issue's DTD entity example. Done means document declarations are disabled or safely rejected, and the regression test confirms the entity is not resolved.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- java
- Ambito
- security
- Tipo di issue
- Bug
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Stato di attività
- Tranquilla
- Chiarezza
- Specificata chiaramente
- Idoneità per principianti
- 84/100